๐บ๐ธ
TPI-Abuse
2026-09-22 23:11:40
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:949110) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:11:32.245412 2026] [security2:error] [pid 6633:tid 6633] [client 89.46.105.109:32358] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "likulikubookings.com"] [uri "/wp-config.php.bak"] [unique_id "arMLJCCd5xx2H1abE4BBogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:55:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:55:51.187633 2026] [security2:error] [pid 1385679:tid 1385679] [client 89.46.105.109:32680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ceezees.com"] [uri "/wp-config.php.bak"] [unique_id "arL5ZwkqZpOMXhUcgYANCQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:40:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:40:23.684265 2026] [security2:error] [pid 31510:tid 31510] [client 89.46.105.109:44080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamworldmovements.com"] [uri "/wp-config.php.bak"] [unique_id "arLnt4fShbLoY-dZ-PyjrAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:15:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:15:18.972522 2026] [security2:error] [pid 3572:tid 3572] [client 89.46.105.109:31734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adm-sal.com"] [uri "/wp-config.php.bak"] [unique_id "arLFtuiuFN4BCqY5vXWD_wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:48:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:48:18.351830 2026] [security2:error] [pid 20301:tid 20301] [client 89.46.105.109:30378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3905ccn.org"] [uri "/wp-config.php.bak"] [unique_id "arK_YtDN_M-89-RymYt4TQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:12:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:12:33.466367 2026] [security2:error] [pid 14343:tid 14343] [client 89.46.105.109:37462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hawleyrentals.com"] [uri "/wp-config.php.bak"] [unique_id "arK3AWSKzdAkxaqHdiis6wAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:46:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:46:15.891296 2026] [security2:error] [pid 10586:tid 10586] [client 89.46.105.109:33470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wbcsnet.com"] [uri "/wp-config.php.bak"] [unique_id "arKw1z96IQJ7lFIs0vsYLQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:39:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:39:38.283624 2026] [security2:error] [pid 15966:tid 15966] [client 89.46.105.109:37366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kugbe.com"] [uri "/wp-config.php.bak"] [unique_id "arKhOhYGJiFGyuO5qu9cPQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:20:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:20:41.608909 2026] [security2:error] [pid 23703:tid 23703] [client 89.46.105.109:21568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samcdevitt.com"] [uri "/wp-config.php.bak"] [unique_id "arJymWv8w-V9P9L1KbbrmgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:28:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:27:54.857786 2026] [security2:error] [pid 28444:tid 28444] [client 89.46.105.109:31178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morivercloggers.com"] [uri "/wp-config.php.bak"] [unique_id "arJKGlBI84Esyu__0qwfbAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 08:54:46
(2 days ago)
[da.kdns.gr] httpd-config-scan: sites=www.agroktima-boukouvala.com; logs=/var/log/httpd/domains/agro ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.agroktima-boukouvala.com; logs=/var/log/httpd/domains/agroktima-boukouvala.com.log; samples=/wp-config.php.bak
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:26:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:26:23.732257 2026] [security2:error] [pid 7639:tid 7639] [client 89.46.105.109:27432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ratalads.com"] [uri "/wp-config.php.bak"] [unique_id "arI7r4IN4255I9mIRD1umwAAAGs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-22 03:39:26
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 02:40:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:210492) triggered by 89.46.105.109 (host109-105-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:39:56.888305 2026] [security2:error] [pid 28969:tid 28969] [client 89.46.105.109:46324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "post-therapyreconditioning.com"] [uri "/.env"] [unique_id "arHqfCFeit32NGIzHSBRvgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2022-02-18 14:02:34
(4 years ago)
89.46.105.109 - - \[18/Feb/2022:21:02:32 +0200\] "POST /WORDPRESS/xmlrpc.php HTTP/1.1" 404 564 "-" " ...
show more
89.46.105.109 - - \[18/Feb/2022:21:02:32 +0200\] "POST /WORDPRESS/xmlrpc.php HTTP/1.1" 404 564 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/60.0.3112.113 Safari/537.36" "-"
89.46.105.109 - - \[18/Feb/2022:21:02:33 +0200\] "POST /wordpress/xmlrpc.php HTTP/1.1" 405 443 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/60.0.3112.113 Safari/537.36" "-"
...
show less
Hacking
Brute-Force
Web App Attack